Wednesday, March 25, 2009
quick hack idea
Get a pineapple (fon router hack, hak5.org for more details) and bring it on a airplane with you. Set up a network called United Airlines Courtesy Wireless or something and see how many people connect. For bonus points, use your cell phone (if you can get a signal) to actually connect them to the internet. While deliberately setting up lots of wireless communication on an airplane may not be the best idea, I'd be willing to bet that everything on the plane is shielded and you probably won't crash the thing. I'd also be willing to be that the first thing people will connect to is their email. More bonus points for convincing the captain or flight attendants that the plane is already equipped with wireless via social engineering so that they announce over the intercom that free wireless is available. You could set up a captive portal that had them download a small file that allowed them to join the 'special airplane kind of wifi' and pack a little dummy program that displays a window with a bogus speed graph and the word "Connected!". Then using the iexpress packing method, also include an exe created from metasploit that executes after the dummy program does. Then it doesn't matter that the internet suddenly doesn't work and the captive portal redirects to a page that explains how, unfortunately, the connection to the ground is currently unavailable due to wind currents or something. By that time, the exe is already running and you have a meterpreter session on every computer that connected. Of course, the classic, easier hack for this situation is just the pineapple asking clients with wifi on for their autoconnect SSID and then silently connecting with them.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment